Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-104831 EXPLOITDB text VERIFIED
2z Project 0.9.5 - 'rating.php' Cross-Site Scripting
by Janek Vind
CVE-2007-2832 EXPLOITDB text VERIFIED
Cisco CallManager - Cross-Site Scripting via CCMAdmin/serverlist.asp Pattern Parameter
Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to CCMAdmin/serverlist.asp (aka the search-form) and possibly other unspecified vectors.
by Marc Ruef
CVE-2007-2747 EXPLOITDB text VERIFIED
rdw_helpers.py <0.3.5.1 - Path Traversal
Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI.
by Jesus Roncero
CVE-2007-2686 EXPLOITDB text VERIFIED
Jetbox CMS 2.1 - Cross-Site Scripting via Login Parameter in Password Reset
Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in a sendpwd task.
by Jesper Jurcenoks
EIP-2026-107440 EXPLOITDB text VERIFIED
GMTT Music Distro 1.2 - 'ShowOwn.php' Cross-Site Scripting
by CorryL
CVE-2007-2854 EXPLOITDB text VERIFIED
bti-tracker < 1.4.1 - SQL Injection via Style or Langue Parameter
Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) style or (2) langue parameter.
by m@ge|ozz
CVE-2007-2857 EXPLOITDB text VERIFIED
ABC Excel Parser Pro < 4.0 - Remote File Inclusion via Parser Path Parameter
PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the parser_path parameter.
by the_Edit0r
CVE-2007-2817 EXPLOITDB text VERIFIED
ol_bookmarks 0.7.4 - SQL Injection via id Parameter
SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Mehmet Ince
CVE-2007-2816 EXPLOITDB text VERIFIED
ol_bookmarks 0.7.4 - Remote Code Execution via Root Parameter in Theme Files
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) test1.php, (2) blackorange.php, (3) default.php, (4) frames1.php, (5) frames1_top.php, (7) test2.php, (8) test3.php, (9) test4.php, (10) test5.php, (11) test6.php, (12) frames1_left.php, and (13) frames1_center.php in themes/.
by ThE TiGeR
CVE-2007-2822 EXPLOITDB text VERIFIED
TutorialCMS <= 1.01 - Authentication Bypass via loggedIn and activated Parameters
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.
by Silentz
CVE-2008-6409 EXPLOITDB text VERIFIED
ol'bookmarks manager 0.7.5 - SQL Injection via id Parameter
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a brain action.
by Mehmet Ince
CVE-2008-6409 EXPLOITDB text VERIFIED
ol'bookmarks manager 0.7.5 - SQL Injection via id Parameter
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a brain action.
by ThE TiGeR
CVE-2007-2685 EXPLOITDB text VERIFIED
Jetbox CMS 2.1 - SQL Injection via View or Login Parameter
Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) login parameter.
by Jesper Jurcenoks
CVE-2007-2774 EXPLOITDB text VERIFIED
SunLight CMS 5.3 - Remote File Inclusion via Root Parameter
Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) _connect.php or (2) modules/startup.php.
by Mehmet Ince
EIP-2026-107598 EXPLOITDB text VERIFIED
HLstats 1.35 - 'hlstats.php' Multiple Cross-Site Scripting Vulnerabilities
by John Martinelli
CVE-2007-2805 EXPLOITDB text VERIFIED
ClientExec < 3.0_beta2 - Cross-Site Scripting via ticketID, view, or fuse Parameters
Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) ticketID, (2) view, and (3) fuse parameters.
by r0t
CVE-2007-1355 EXPLOITDB text VERIFIED
Tomcat 4.0.0-4.0.6, 4.1.0-4.1.36, 5.0.0-5.0.30, 5.5.0-5.5.23, 6.0.0-6.0.10 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.
by Ferruh Mavituna
CVE-2007-2778 EXPLOITDB text VERIFIED
MolyX BOARD 2.5.0 - Directory Traversal via Lang Parameter
Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to index.php and other unspecified PHP scripts.
by MurderSkillz
CVE-2007-2779 EXPLOITDB text VERIFIED
libstats < 1.0.3 - Remote File Inclusion via rInfo[content] Parameter
PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rInfo[content] parameter.
by Mehmet Ince
CVE-2007-2780 EXPLOITDB text VERIFIED
PsychoStats <3.0.6b - Info Disclosure
PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a path in an error message.
by kefka
CVE-2007-2792 EXPLOITDB text VERIFIED
Yet another Newsletter Component (YaNC) < 1.5 beta 3 - SQL Injection via listid Parameter
SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter to index.php. NOTE: some of these details are obtained from third party information.
by Mehmet Ince
CVE-2007-2793 EXPLOITDB text VERIFIED
Geeklog 2.x - Remote Code Execution
PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter.
by diesl0w
CVE-2007-2762 EXPLOITDB text VERIFIED
Build it Fast 0.4.1 - Remote File Inclusion via PEAR Directory or System Directory Parameter
Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the pear_dir parameter to Base/Application.php, or the (2) sys_dir parameter to (a) Footer.php, (b) widget.BifContainer.php, (c) widget.BifRoot.php, (d) widget.BifRoot2.php, (e) widget.BifRoot3.php, or (f) widget.BifWarning.php in Widgets/Base/.
by Alkomandoz Hacker
CVE-2007-2752 EXPLOITDB text VERIFIED
RunawaySoft Haber <1.0 - SQL Injection
SQL injection vulnerability in devami.asp in RunawaySoft Haber portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by kerem125
CVE-2007-2908 EXPLOITDB text VERIFIED
vBulletin < 3.6.5 - Cross-Site Scripting via Calendar Title Field
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action.
by laurent gaffie